Method, system, electronic device and storage medium for generating network topology graph

By deploying a zero-trust gateway in the network and combining active and passive scanning and detection technologies to generate and update network topology maps, the problem of inefficient topology discovery in the existing technology is solved, and automated and real-time network management is achieved.

CN115834395BActive Publication Date: 2025-08-12BEIJING CHANGYANG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211475202.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-23
Publication Date
2025-08-12
Estimated Expiration
2042-11-23

AI Technical Summary

Technical Problem

In the prior art, network topology discovery means are poor in versatility, low equipment detection efficiency, untimely updates, and inconvenient maintenance, making it difficult to meet the management needs of complex networks.

Method used

The zero-trust gateway is deployed using a zero-trust architecture, combining active scanning and passive scanning detection to obtain asset equipment information, generate network topology maps, and dynamically update through zero-trust network interactive data.

Benefits of technology

It realizes automatic generation and real-time update of network topology maps, reduces manual drawing workload, improves detection efficiency, and ensures data accuracy and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834395B_ABST
    Figure CN115834395B_ABST
Patent Text Reader

Abstract

The present application proposes a method and system for generating a network topology map, which includes: scanning and detecting IP addresses in the network to obtain information about asset devices in the network; deploying a zero-trust gateway to obtain zero-trust network interaction data of asset devices, wherein the zero-trust gateway is deployed at the data access front end of the asset device; generating a network topology map based on the information of the asset device and the zero-trust network interaction data. This solution proposes to automatically generate a network topology map based on a zero-trust architecture, effectively reducing the workload of manually drawing a topology map, and at the same time, based on the network interaction data obtained by the zero-trust gateway, it can automatically verify and correct the manually adjusted network topology map structure. Furthermore, the method of scanning and detecting IP addresses in the network includes a combination of active scanning and detection and passive scanning and detection. Combining and merging the data obtained by active scanning and detection and passive scanning and detection helps to fully detect and timely update the asset devices in the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of information security technology, and specifically relates to a network topology map generation method, system, electronic device and storage medium. Background Art

[0002] Network topology refers to the arrangement and relationships of links and nodes on a network. It is a crucial tool for network administrators to configure, monitor performance, and diagnose network devices. As networks grow in size, their structures become more complex, and device types become more diverse, the difficulty of discovering and maintaining network topologies increases accordingly. However, existing network topology discovery methods still suffer from issues such as limited versatility, low device detection efficiency, delayed updates, and inconvenient maintenance. Summary of the Invention

[0003] In response to the above problems, on the first aspect, this application proposes a method for generating a network topology map, including: scanning and detecting IP addresses in the network to obtain information about asset devices in the network; deploying a zero-trust gateway to obtain zero-trust network interaction data of asset devices, wherein the zero-trust gateway is deployed at the data access front end of the asset devices; generating a network topology map based on the asset device information and the zero-trust network interaction data. Since the zero-trust network limits the scope of permitted scanning, the topology map obtained through the zero-trust network is the asset devices discovered through a security scan conducted within the controllable range of the network scan, which can avoid the problem of other sensitive user data that may be obtained at the same time in other ways of obtaining asset devices; at the same time, the zero-trust architecture is an architecture for managing and controlling assets within the enterprise, and the location of the asset devices therein has regional attributes, based on which the identified asset device information can be dynamically divided into regions during the network topology map generation process.

[0004] Furthermore, when the network interaction data of the asset device is updated, a network topology map is generated based on the updated asset device information and the network interaction data.

[0005] Furthermore, scanning and probing IP addresses on the network can include a combination of active and passive scanning. Combining and merging the data obtained from active and passive scanning facilitates comprehensive detection and timely updates of network assets, avoiding the potential data inaccuracies that can arise from a single scanning method.

[0006] Furthermore, the active scanning and detection specifically includes performing active scanning and detection on a fixed network segment or a manually configured IP address library to obtain a surviving IP address.

[0007] Furthermore, passive scanning detection specifically includes analyzing source-to-end traffic in the network, obtaining IP addresses in the network and passive detection network interaction data of asset devices for generating a network topology map.

[0008] Furthermore, the asset device information includes at least one of an IP address, a port, an asset type, a location, and an operating system.

[0009] On the second aspect, the present application proposes a network topology map generation system, including: a scanning and detection module, configured to scan and detect IP addresses in the network to obtain information about asset devices in the network; a zero-trust gateway module, configured to obtain zero-trust network interaction data of asset devices, and the zero-trust gateway is deployed at the data access front end of the asset device; a network topology map generation module, which generates a network topology map based on the information of the asset device and the zero-trust network interaction data.

[0010] Furthermore, the method of scanning and detecting IP addresses in the network includes a combination of active scanning and detection and passive scanning and detection.

[0011] In a third aspect, the present application proposes an electronic device for generating a network topology map, comprising: a processor; a memory for storing processor-executable instructions; wherein the processor implements any of the methods described in the first aspect by running the executable instructions.

[0012] In a fourth aspect, the present application proposes a computer-readable storage medium for generating a network topology diagram, on which one or more computer programs are stored, characterized in that when the one or more computer programs are executed by a computer processor, any method described in the first aspect is implemented.

[0013] The method and system proposed in this application for automatically generating network topology maps based on a zero-trust architecture can effectively reduce the workload of manually drawing topology maps and automatically correct errors. At the same time, the combination of active and passive detection and scanning methods can capture complete asset equipment information in the network and update it in a timely and dynamic manner, with high detection efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] The accompanying drawings help further understand the present application. The elements of the drawings are not necessarily in scale with each other. For ease of description, only the parts relevant to the invention are shown in the drawings.

[0015] Figure 1 This is a flowchart of a method for generating a network topology diagram in a specific embodiment of the present application;

[0016] Figure 2 This is a diagram showing an example of data obtained through active scanning detection in another specific embodiment of the present application;

[0017] Figure 3 This is a diagram of a network interaction example obtained by passive scanning detection in another specific embodiment of the present application;

[0018] Figure 4This is a schematic diagram of a zero-trust architecture deployment in another specific embodiment of the present application;

[0019] Figure 5 A schematic diagram of a zero-trust architecture in another specific embodiment of this application

[0020] Figure 6 This is a schematic diagram of network interaction traffic data integrated based on a zero-trust control platform in another specific embodiment of the present application;

[0021] Figure 7 A schematic diagram of the generation process of a network topology diagram in another specific embodiment of the present application

[0022] Figure 8 This is an example diagram of a network topology diagram generated in another specific embodiment of the present application;

[0023] Figure 9 This is a schematic diagram of the network topology diagram generation system structure in another specific embodiment of the present application. DETAILED DESCRIPTION

[0024] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention.

[0025] Figure 1 1 is a flow chart of a method for generating a network topology diagram according to an embodiment of the present application, the method comprising:

[0026] S1, scans and detects IP addresses in the network to obtain information about asset devices in the network;

[0027] S2, deploy a zero-trust gateway to obtain zero-trust network interaction data of asset devices, where the zero-trust gateway is deployed at the data access front end of the asset device;

[0028] S3, generates a network topology map based on asset device information and zero-trust network interaction data.

[0029] It is understood that in practical applications, the above steps do not necessarily have to be performed in sequence.

[0030] The method described in this embodiment uses a zero-trust gateway to obtain network interaction data from asset devices and automatically generates a network topology map based on the information about asset devices in the automated network. Zero-trust architecture deployment and protection measures are currently a popular solution for protecting intranet resources, minimizing authorized access, and strictly controlling data security. During intranet deployment and use, all traffic data within the intranet must be parsed, verified, and checked for authorization. Therefore, the zero-trust gateway can obtain network interaction data from asset devices and use it to generate a network topology map.

[0031] In a specific embodiment, active scanning and passive scanning are combined to scan and detect IP addresses in the network. By configuring devices with active scanning and passive scanning functions, information about asset devices in the network can be obtained in a combined active and passive manner.

[0032] Figure 2 This is an example of data obtained by active scanning and detection in another preferred embodiment of this application. In this embodiment, active scanning and detection specifically involves actively scanning a fixed network segment or a manually configured IP address library within a specified time period, scanning the surviving IP addresses in the network, and obtaining information such as the operating system, version, model, and features related to the corresponding IP address. Figure 2 .

[0033] Figure 3 This is a network interaction example diagram obtained by passive scanning detection in another preferred embodiment of this application. In this embodiment, passive scanning detection specifically analyzes and processes all traffic passing through the network, analyzes source-to-end traffic, and parses out IP addresses and their operating systems, versions, models, features, etc., wherein a network interaction diagram can also be obtained based on source-to-end traffic, see Figure 3 It can be seen that passive scanning can obtain information about asset devices in the network and network interaction data, which can be used to draw topology maps.

[0034] Furthermore, data from active and passive scanning probes can be merged to obtain comprehensive asset device information. Specifically, the data from active and passive scanning probes can be compared using the IP address and MAC address, and identical data can be merged. Data from passive scanning that did not detect an IP address during active probing is classified as pending asset data. This data can then be manually confirmed or verified by querying asset data obtained through the Zero Trust Gateway.

[0035] Figure 4 This is a schematic diagram of the zero trust architecture deployment in another embodiment of the present application. Figure 4 In this embodiment, a zero-trust gateway is deployed at the data access front end of the asset device to be protected, so that all access data traffic is verified through the zero-trust network to ensure that the traffic access is legal, thereby protecting the security of access to hardware devices such as intranet data storage devices and servers.

[0036] Figure 5 FIG. 1 is a schematic diagram of a zero-trust architecture in another specific embodiment. Figure 5As shown, the zero-trust architecture includes an infrastructure module for implementing functions such as logging, communication, monitoring, and interaction; a data acquisition module for collecting data obtained from active scanning and passive scanning; a data processing module for implementing functions such as data filtering, data cleaning, data storage, and statistical analysis; and a data display module for displaying statistical reports and alarm notifications to achieve data visualization and observability. Furthermore, a zero-trust control platform is deployed in the zero-trust architecture as a central control platform for managing and controlling zero-trust gateways and zero-trust clients, and performs tasks such as policy issuance, data aggregation, and analysis on zero-trust gateways and zero-trust clients. Specifically, the zero-trust control platform obtains asset access interaction records, generates a network interaction data table, and stores it in the database, thereby obtaining network interaction data of asset devices. Figure 6 This is a schematic diagram of network interaction traffic data integrated based on the zero trust control platform in a specific embodiment. According to the information of the asset equipment, the network interaction data table saved by the zero trust control platform is called to integrate the network interaction data. Figure 6 The zero-trust control platform can clearly identify the network interaction data of real asset devices, as well as related information such as whether the data flow is one-way or two-way, thereby realizing the generation of a network topology map.

[0037] Figure 7 This is a schematic diagram of the generation process of a network topology diagram in another embodiment of the present application. Figure 7 In this embodiment, the data obtained by combining active scanning detection and passive scanning detection is cleaned, and then asset data is merged and data flow analysis is performed. Then, combined with the zero-trust network interaction data obtained in the zero-trust gateway, a dynamically updated network topology map is generated.

[0038] Figure 8 This is an example of a network topology diagram generated in another embodiment of the present application. The zero-trust gateway can obtain the status of the protected asset equipment (such as survival status or offline status), real-time traffic information passing through the asset, and information about the area where the asset is located (such as a factory area or office area, etc.). Based on the identified asset type, a dynamic topology diagram with real-time updates of traffic status can be achieved by region, allowing intuitive observation of the asset distribution in the network. Figure 8 , where each icon is a confirmed asset, the IP address below the icon represents the IP attribute of the asset, the arrow represents the flow data from one asset to another, the arrow above indicates the real-time data flow, and the dotted box represents different factories or different areas, such as Figure 8 It can be seen that the network area includes Factory Area 1 and Factory Area 2. The assets and equipment of Factory Area 1 include two servers, and the assets and equipment of Factory Area 2 include three hosts, two of which are online and one is offline. There is a switch connecting Factory Area 1 and Factory Area 2, and there is real-time traffic.

[0039] Figure 9 1 is a schematic diagram of a network topology diagram generating system 900 according to an embodiment of the second aspect of the present application, the system comprising:

[0040] Scanning and detection module 901 is configured to scan and detect IP addresses in the network and obtain information about asset devices in the network;

[0041] Zero Trust Gateway Module 902, deployed at the data access front end of the asset device;

[0042] The network topology map generation module 903 is configured to obtain network interaction data of asset devices based on the zero-trust gateway, and generate a network topology map based on the information of the asset devices and the network interaction data.

[0043] On the other hand, the present application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiment; or it may exist independently without being assembled into the electronic device. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed by the electronic device, the electronic device is caused to: scan and detect IP addresses in the network to obtain information about asset devices in the network; deploy a zero-trust gateway to obtain zero-trust network interaction data of the asset devices, wherein the zero-trust gateway is deployed at the data access front end of the asset devices; and generate a network topology map based on the asset device information and the zero-trust network interaction data.

[0044] Based on the description of the above embodiments, it can be understood that the network topology map generation method and system proposed in this application automatically generate network topology maps based on the zero-trust architecture, which can reduce the workload of manually drawing topology maps, and at the same time automatically verify and correct the network structure of the manually adjusted topology maps; based on the zero-trust gateway to obtain data access traffic, etc., the topology map can be dynamically updated, and the asset survival status, data traffic status, and access status can be displayed in real time, and the network connection and access status can be displayed globally and macroscopically.

[0045] Although the contents of the present application are specifically shown and described in conjunction with the preferred embodiments, those skilled in the art should understand that various changes made to the present application in form and details without departing from the spirit and scope of the present application as defined by the appended claims and without making any creative work are within the scope of protection of the present application.

Claims

1. A method for generating a network topology graph, characterized in that: include: Scan and detect IP addresses in the network to obtain information about assets and devices in the network; the scanning and detection of IP addresses in the network includes a combination of active scanning and detection and passive scanning and detection; the passive scanning and detection specifically includes analyzing source-to-end traffic in the network to obtain IP addresses in the network and passive detection network interaction data of assets and devices to generate a network topology map; Deploy a zero-trust gateway to obtain zero-trust network interaction data of the asset device, wherein the zero-trust gateway is deployed at the data access front end of the asset device; Generate a network topology map based on the asset device information and the zero-trust network interaction data.

2. The network topology diagram generation method according to claim 1, characterized in that: When the zero-trust network interaction data of the asset device is updated, a network topology map is generated according to the updated information of the asset device and the zero-trust network interaction data.

3. The network topology diagram generation method according to claim 1, characterized in that: The active scanning and detection specifically includes performing active scanning and detection on a fixed network segment or a manually configured IP address database to obtain a surviving IP address.

4. The network topology diagram generation method according to claim 1, characterized in that: The asset device information includes at least one of an IP address, a port, an asset type, a location, and an operating system.

5. A network topology diagram generation system, characterized in that: include: A scanning and detection module configured to scan and detect IP addresses in the network and obtain information about assets and devices in the network; the scanning and detection of IP addresses in the network includes a combination of active scanning and detection and passive scanning and detection; the passive scanning and detection specifically includes analyzing source-to-end traffic in the network to obtain IP addresses in the network and passive detection network interaction data of assets and devices for generating a network topology map; A zero-trust gateway module is configured to obtain zero-trust network interaction data of the asset device, and the zero-trust gateway is deployed at the data access front end of the asset device; A network topology map generation module generates a network topology map based on the information of the asset device and the zero-trust network interaction data.

6. An electronic device for generating a network topology map, comprising: processor; a memory for storing processor-executable instructions; The processor implements the method according to any one of claims 1 to 4 by running the executable instructions.

7. A computer-readable storage medium for generating a network topology diagram, storing one or more computer programs, characterized in that: When the one or more computer programs are executed by a computer processor, the method according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Power monitoring system-oriented network topology remote visual monitoring method

    CN109768880A

  • Industrial control network topological graph generation method based on active and passive detection

    CN112671553A